Updated python-tornado packages fix security vulnerabilities
Publication date: 02 Oct 2026Modification date: 02 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-49853 , CVE-2026-49854 , CVE-2026-49855
Description
Tornado: Authorization header forwarded across cross-origin redirects in
SimpleAsyncHTTPClient
Tornado has out-of-bounds memory access via C extension
tornado AsyncHTTPClient accumulates decompressed chunks without size
limit (gzip bomb)
References
- https://bugs.mageia.org/show_bug.cgi?id=35712
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/GZ7Q55UOVFEKZDAHBHES3HJS2PZ4OQHV/
- https://www.cve.org/CVERecord?id=CVE-2026-49853
- https://www.cve.org/CVERecord?id=CVE-2026-49854
- https://www.cve.org/CVERecord?id=CVE-2026-49855
SRPMS
10/core
- python-tornado-6.5.10-1.1.mga10